Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti, Michael D. Bailey, Fabian Monrose
Abstract
—The Uniform Domain Name Dispute Resolution Policy (UDRP) seeks to balance two competing goals: empowering trademark holders to swiftly address cybersquatting cases targeting their brands and protecting domain registrants from aggressive legal tactics by overreaching trademark holders. Since its inception, the UDRP has become the de facto dispute resolution mechanism for over two thousand domain extensions, a substantial increase from the original three. However, despite its successes, critics argue that the policy enables practices that undermine trust and fairness. Unfortunately, meaningful reform efforts have stalled due to the absence of large-scale structured data, limiting empirical evaluations and leaving foundational questions unanswered for more than two decades. To address this long-standing gap, we trained models to extract structured data from 90,153 UDRP dispute proceedings, enabling the most comprehensive empirical analysis of the policy to date. Our findings shed light on several issues, showing evidence of forum shopping in almost one-third of all the disputes, potential conflicts of interest in 43 cases, and delays (by many parties) that fall well outside the expected response times—all of which impact the perceived fairness and efficiency of UDRP. Beyond eroding trust, those issues create serious security challenges: 2,751 malicious domains remained under malicious actors’ con-trol for up to four months after a panel ordered their transfer. Overall, our findings underscore the need for policy reform to help restore trust and improve transparency in the Internet’s de facto standard for countering trademark infringement. Based on our discoveries, we recommend introducing greater automation, strengthening oversight, and enforcing clearer compliance rules to ensure that the UDRP remains a reliable tool for trademark-based name disputes—especially as the Internet continues to expand with new generic top-level domains and the digital environment becomes increasingly hostile to users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 550e2d10-c963-4205-9340-db65a357b43dBuilds on4
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates et al.USENIX Security 2018 · 32 citations
- The Imitation Game: Exploring Brand Impersonation Attacks on Social Media PlatformsBhupendra Acharya, Dario Lazzaro, Efrén López-Morales, Adam Oest et al.USENIX Security 2024 · 7 citations
- The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Michael D. Bailey et al.NDSS 2025
Related papers
- Understanding the Implementation and Security Implications of Protective DNS ServicesMingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu et al.NDSS 2024
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon et al.S&P 2016 · 76 citations
- Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsYevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi et al.CCS 2025 · 1 citation
- Misty Registry: An Empirical Study of Flawed Domain Registry OperationMingming Zhang, Yunyi Zhang, Baojun Liu, Haixin Duan et al.USENIX Security 2025
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
